NIST SP 800-53 Rev 5
CP - Contingency Planning

NIST SP 800-53 Rev 5 NIST800-CP-10: CP-10 System Recovery and Reconstitution

Provide for the recovery and reconstitution of the system to a known state within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] after a disruption, compromise, or failure.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 147 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • NIST-CSF-RS.MI-02 Incidents are eradicated

FedRAMP High · 6 controls

  • CP-10 System Recovery and Reconstitution
  • CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2))
  • CP-2(3) Resume Mission and Business Functions
  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))

FedRAMP Moderate · 6 controls

  • CP-10 System Recovery and Reconstitution
  • CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2))
  • CP-2(3) Resume Mission and Business Functions
  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))

CIS Controls v8 · 4 controls

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO 27002:2022 · 3 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

NIST SP 1800-32 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • PICERL-C2 System Backup
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

SOC 2 · 3 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC7.5 CC7.5 - Incident Recovery

C5 (Germany) · 2 controls

  • C5-BCM-03 Planning business continuity
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • CFTC-SS-25 Same Day Recovery Time Objective for Critical Entities
  • CFTC-SS-9 Next Business Day Recovery Time Objective

DORA · 2 controls

ISO 22301:2019 · 2 controls

  • 8.4 Business continuity plans and procedures
  • 8.4.5 Recovery

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO 27001:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

HIPAA Security Rule · 1 control

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

  • CP-10 CP-10 System Recovery and Reconstitution
  • CP-10 CP-10 System Recovery and Reconstitution
  • CP-10 CP-10 System Recovery and Reconstitution
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security

PCI P2PE · 1 control

  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 1 control

  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 1 control

  • PCI-SSF-12 Disaster recovery procedures

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 1 control

  • PTESPHASE-3 Threat Modeling
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CP - Contingency Planning

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CP-10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 147 it maps to, and the evidence behind each claim, over MCP and REST.